BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Apr 2026 | Dane anonimowe (Burmistrza Miasta i Gminy D.)UODO imposed an administrative fine of 7,700 PLN on Anonymous data (Mayor of D. Municipality). The sanction resulted from failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. | PL | UODO | GDPR | €1,807 | ↗ |
| 18 Oct 2019 | Dane anonimowe (Burmistrza G. karę pieniężną w kwocie 40.000 zł)UODO found a breach of the principles of lawful processing and confidentiality. A fine of PLN 40,000 was imposed, together with an order to bring processing operations into compliance with data protection rules. | PL | UODO | GDPR | €9,336 | ↗ |
| 15 Oct 2025 | Dane anonimowe (B. Sp. z o.o. z siedzibą w M. za naruszenie przepisu art. 33 ust. 1 rozporządzenia 2016/679)UODO imposed an administrative fine on B. Sp. z o.o. for failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay and, at the latest, within 72 hours of becoming aware of it. The case concerns the reporting obligation under Article 33(1) GDPR. | PL | UODO | GDPR | €9,519 | ↗ |
| 14 Oct 2021 | Dane anonimowe (Bank Z. S.A.)The Polish DPA (UODO) imposed an administrative fine of PLN 363,832 on Bank Z. S.A. The authority found that the bank failed to notify the supervisory authority of a personal data breach and did not inform the affected individuals. | PL | UODO | GDPR | €79,625 | ↗ |
| 12 Nov 2024 | Dane anonimowe (A. z siedzibą w W. przy ul.)The Polish DPA (UODO) imposed administrative fines on the controller and the processor for breaches of GDPR obligations. The case concerned, among others, integrity and confidentiality, accountability, data protection by design, processor arrangements, and security measures. | PL | UODO | GDPR | €351,000 | ↗ |
| 20 May 2024 | Dane anonimowe (A. Spółka Akcyjna z siedzibą w U., ul.)UODO imposed an administrative fine of PLN 1,440,549 on A. Spółka Akcyjna. The authority found breaches of the integrity and confidentiality principle and the obligation to implement appropriate data security measures. | PL | UODO | GDPR | €338,000 | ↗ |
| 29 Apr 2024 | Dane anonimowe (A. Sp. k. z siedzibą w T.)UODO imposed a PLN 238,345 administrative fine on A. Sp. k. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing, including the use of external storage media. The authority also found a lack of regular testing, measurement, and evaluation of the effectiveness of the security measures in place. | PL | UODO | GDPR | €55,103 | ↗ |
| 30 Aug 2023 | Dane anonimowe (A. S.A. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 56,592 on the company. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for its tasks. | PL | UODO | GDPR | €12,652 | ↗ |
| 28 Feb 2017 | DALMORRIS, S.L.DALMORRIS, S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts this type of communication without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 14 Jun 2017 | DALMORRIS, S.L.DALMORRIS, S.L. was fined by the AEPD in the amount of 600 EUR for sending an unsolicited commercial email. The conduct breached Article 21.1 of the LSSI, which prohibits unwanted marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 06 Jun 2018 | Dalmesse Italia s.r.l.Dalmesse Italia s.r.l. was fined €22,000 by the Italian supervisory authority, Garante. The case concerned the processing of personal data, including sensitive health data, without proper compliance with data protection rules. | IT | Garante | GDPR | €22,000 | ↗ |
| 20 Dec 2010 | DAI SOFTWARE CENTRE S.L.DAI SOFTWARE CENTRE S.L. was fined by the AEPD in the amount of €600 for sending unsolicited commercial emails. The case concerned a breach of Article 21.1 of the LSSI, which prohibits marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 19 Jan 2017 | D’Agostino Domenico FedeleD’Agostino Domenico Fedele was fined EUR 9,600 by the Garante for failing to provide individuals with the required data protection information. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,600 | ↗ |
| 09 Nov 2021 | Cyrana España General S.L.Cyrana España General S.L. was fined by the AEPD in the amount of 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account. | ES | AEPD | GDPR | €5,000 | ↗ |
| 25 Jul 2021 | CYNGASA, S.L.CYNGASA, S.L. was fined by the AEPD EUR 5,000 for transferring an employee’s personal data to another company without consent. The authority found this conduct to be a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 03 Feb 2021 | Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion. | NO | Datatilsynet | GDPR | €19,316 | ↗ |
| 12 May 2025 | CV PRO CONSULT S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation in April 2025 at CV PRO CONSULT S.R.L. and found a GDPR violation. As a result, a fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 14 May 2025 | CVA TAX & FINANCE S.R.L.In April 2025, ANSPDCP completed an investigation at CVA TAX & FINANCE S.R.L. and found a GDPR violation. As a result, a fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 05 Sept 2013 | CURTIPETRIZZILANDIA S.a.sCURTIPETRIZZILANDIA S.a.s was fined by the Garante in the amount of 2,400 EUR for providing inadequate data protection information on its website booking form. The case concerned breaches of the information duties under the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Sept 2022 | Curtea Veche Publishing SRLCurtea Veche Publishing SRL was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |